CVE-2024-24756
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-24756 is a vulnerability affecting the Crafatar service, which serves Minecraft avatars for use in external applications. The issue arises from the server's ability to serve files outside of the `lib/public/` directory, potentially exposing confidential information. Instances running behind Cloudflare are not influenced by this vulnerability. However, instances using the Docker container, as outlined in the README, are susceptible, limiting the impact to files within the container. By default, all files within the container are publicly accessible in the repository, exacerbating the issue. This vulnerability has been mitigated in version 2.1.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.